Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Product Security Engineer image - Rise Careers
Job details

Senior Product Security Engineer

Senior Product Security Engineer

Toast is driven by building the restaurant platform that helps restaurants adapt, take control, and get back to what they do best: building the businesses they love.

Product Security at Toast isn't just about running tools and reporting vulnerabilities – we're the vigilant chefs ensuring the Toast never gets burned. We bake security into every layer of our products, from the first sprinkle of an idea to the final serving of a fully-baked solution. Our team is the secret ingredient that makes Toast's digital recipe both delicious and secure. We collaborate closely with R&D, seasoning the development process with robust security measures that protect the services and applications our customers rely on to run their businesses. 

Like master chefs, we blend cutting-edge technology with strategic thinking, kneading security into the dough of every product we create. By joining our Product Security team, you'll be part of the kitchen crew that keeps our customers' trust from going stale. You'll tackle complex challenges that have real-world impact, helping to serve up a safer, more secure digital experience for businesses that count on Toast every day. It's not just about finding vulnerabilities – it's about crafting a recipe for digital trust that keeps our customers coming back for more.

About this roll* (Responsibilities) 

  • Identify, triage, and provide remediation guidance for application vulnerabilities.
  • Select, implement, design, or build tools to thwart attacks of all shapes and sizes.
  • Improve developer tooling and adoption to build a more robust SSDLC.
  • Practice a #OneTeam attitude to help other Toast teams make informed, security-conscious. decisions when building new software.
  • Support and expand the Security Champions program, providing edge security guidance and training.
  • Assist incident response teams with application security expertise and tools.
  • Think like an attacker to identify weaknesses in application architecture.

In addition:

  • Support Cloud and Network Infrastructure Engineering's implementation of edge security solutions.
  • Influence the implementation and rule maintenance of our WAF strategy and other edge security solutions.
  • Advise on WAF rules and policies to protect against common and emerging threats.
  • Conduct regular assessments of our edge security posture and recommend improvements.
  • Provide expertise on Content Delivery Networks (CDNs) and their security features.

Do you have the right ingredients*? (Requirements)

  • 5+ years of experience in application security
  • Strong knowledge of common web application vulnerabilities and edge-based attack vectors.
  • Proficiency in analyzing web traffic patterns and identifying anomalies.
  • Knowledge of compliance standards relevant to the financial industry (e.g., PCI DSS, SOC 2).
  • Excellent problem-solving skills and ability to think creatively about edge security challenges.
  • Strong communication skills, with the ability to explain complex edge security concepts to both technical and non-technical audiences.
  • Strong understanding of cloud application architecture and common weaknesses.

Special Sauce* (Nonessential Skills/Nice to Haves)

Experience with:

  • Understanding of WAF configuration, tuning, and optimization.
  • Popular WAF solutions (e.g., AWS WAF, Cloudflare, Akamai, ModSecurity).
  • Familiarity with CDN technologies and their security features.
  • Cloud and container security technologies and SSDLC tooling (e.g. SAST/DAST/SCA)
  • Infrastructure-as-code (IaC) technologies like Terraform to manage cloud security services
  • Securing financial technologies

Relevant security certifications (e.g., CCSP, CISSP, CSSLP) are a plus

 

Diversity, Equity, and Inclusion is Baked into our Recipe for Success

At Toast, our employees are our secret ingredient—when they thrive, we thrive. The restaurant industry is one of the most diverse, and we embrace that diversity with authenticity, inclusivity, respect, and humility. By embedding these principles into our culture and design, we create equitable opportunities for all and raise the bar in delivering exceptional experiences.

We Thrive Together

We embrace a hybrid work model that fosters in-person collaboration while valuing individual needs. Our goal is to build a strong culture of connection as we work together to empower the restaurant community. To learn more about how we work globally and regionally, check out: https://careers.toasttab.com/locations-toast.

Apply today!

Toast is committed to creating an accessible and inclusive hiring process. As part of this commitment, we strive to provide reasonable accommodations for persons with disabilities to enable them to access the hiring process. If you need an accommodation to access the job application or interview process, please contact candidateaccommodations@toasttab.com.

Average salary estimate

$100000 / YEARLY (est.)
min
max
$80000K
$120000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Product Security Engineer, Toast

Are you looking to make a significant impact on digital security? Join Toast as a Senior Product Security Engineer and be a vital part of our mission to support restaurants in adapting and thriving. At Toast, we believe in building security into our products from the ground up. You won't just be identifying vulnerabilities; you'll be an integral part of our team that ensures our digital solutions remain trustworthy and secure. You'll collaborate closely with our R&D teams, employing advanced security measures that protect the services our customers rely on. As a Senior Product Security Engineer, your role will involve identifying and triaging application vulnerabilities while also selecting and implementing tools to prevent diverse attacks. You’ll help enhance developer tools and processes to create a more robust secure software development lifecycle (SSDLC). Your insights will be invaluable in guiding teams toward making informed security-conscious decisions. Additionally, you’ll assist with incident response and contribute to our edge security strategies, collaborating with our Cloud and Network Infrastructure team. If you have a strong background in application security and a passion for creating secure digital experiences, Toast is the perfect place for you to grow your skills and help nurture the restaurant industry's future. Apply now, and let's craft a recipe for success together!

Frequently Asked Questions (FAQs) for Senior Product Security Engineer Role at Toast
What are the responsibilities of a Senior Product Security Engineer at Toast?

As a Senior Product Security Engineer at Toast, you will be responsible for identifying and triaging application vulnerabilities, providing remediation guidance, and selecting and implementing tools to thwart various attack vectors. Your involvement will extend to improving developer tooling and practices to support a robust secure software development lifecycle (SSDLC), and you'll play a key role in educating and guiding other teams in making informed security decisions.

Join Rise to see the full answer
What qualifications do I need to apply for the Senior Product Security Engineer position at Toast?

To apply for the Senior Product Security Engineer position at Toast, you should have a minimum of 5 years of experience in application security. A strong understanding of common web application vulnerabilities and edge-based attack vectors is crucial, along with proficiency in analyzing web traffic patterns. Familiarity with compliance standards like PCI DSS and strong problem-solving skills will also be essential.

Join Rise to see the full answer
How does Toast ensure diversity and inclusion within its Senior Product Security Engineer team?

Toast is committed to diversity, equity, and inclusion in the workplace, especially within the Senior Product Security Engineer team. We strive to create a culture that embraces diverse backgrounds and perspectives, providing equitable opportunities for all employees. This commitment ensures that our team not only competes at the highest levels but also creates exceptional experiences for our restaurant partners.

Join Rise to see the full answer
What tools and technologies will I work with as a Senior Product Security Engineer at Toast?

In your role as a Senior Product Security Engineer at Toast, you will work with a variety of tools and technologies, including web application firewalls (WAF), content delivery networks (CDNs), and security testing tools for the secure software development lifecycle (SSDLC) such as SAST and DAST. Knowledge of cloud security solutions and infrastructure-as-code technologies like Terraform is also a plus.

Join Rise to see the full answer
What type of team environment can a Senior Product Security Engineer expect at Toast?

At Toast, the team environment for a Senior Product Security Engineer is collaborative and supportive, fostering a #OneTeam attitude. You will be part of a driven group that works closely together to tackle complex security challenges, offering guidance and expertise across various departments to ensure that security is an integral part of the development process.

Join Rise to see the full answer
Common Interview Questions for Senior Product Security Engineer
Can you explain a security vulnerability you have encountered and how you addressed it?

To effectively answer this question, detail a specific vulnerability you faced, outlining its impact, what steps you took to remediate it, and the tools or methodologies you used. Explain how your actions helped secure the application and highlight any changes you implemented to prevent similar issues in the future.

Join Rise to see the full answer
How do you prioritize vulnerabilities in a software development environment?

Discuss how you evaluate vulnerabilities based on factors such as severity, impact, exploitability, and the sensitivity of data handled by the application. Share your approach to communicating these priorities with development teams and how you work together to mitigate risks accordingly.

Join Rise to see the full answer
What experience do you have with secure software development lifecycle (SSDLC) practices?

In your response, describe your familiarity and experience with SSDLC principles. Share specific practices you've implemented or improved upon, such as integrating security testing into development stages and training developers on secure coding techniques.

Join Rise to see the full answer
Can you describe your experience with web application firewalls (WAF)?

Share your hands-on experience with configuring, tuning, and optimizing WAFs. Discuss particular instances where a WAF helped mitigate attacks or protect against specific threats, emphasizing your role in those processes.

Join Rise to see the full answer
How do you stay updated on the latest security threats and vulnerabilities?

Discuss your approach to continuous learning, including following security news sources, participating in relevant forums, attending conferences, and engaging with communities. This shows your proactive mindset in staying informed on trends in cybersecurity.

Join Rise to see the full answer
What security certifications do you hold, and how do they benefit your work?

List relevant security certifications you possess, such as CCSP, CISSP, or CSSLP. Explain how each certification has improved your knowledge base, skills, and ability to contribute to securing applications effectively.

Join Rise to see the full answer
Can you describe a time you worked with non-technical stakeholders on security concepts?

Provide an example that demonstrates your ability to communicate complex security concepts in simple terms. Highlight your approach to ensuring that non-technical stakeholders could understand and make informed decisions related to security.

Join Rise to see the full answer
How would you conduct a security assessment of a web application?

Outline the steps you would take, including planning, reconnaissance, scanning for vulnerabilities, manual testing, and analyzing results. Emphasize the importance of documentation and communication of findings to development teams to drive the remediation process.

Join Rise to see the full answer
What is your approach to implementing security training for development teams?

Share your strategies for creating engaging training programs, including tailored content that addresses industry-specific threats. Discuss how ongoing education is vital to maintaining a security-first mindset across teams.

Join Rise to see the full answer
Why do you want to work as a Senior Product Security Engineer at Toast?

Reflect on your passion for security and how it aligns with Toast's mission to support the restaurant industry. Share what aspects of the role excite you, including the opportunity to work on challenging security problems and collaborate with diverse teams.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 11 days ago

Join Toast as a Software Engineer II to develop and support enterprise-level features for their dynamic hospitality software platform.

Photo of the Rise User
Posted 13 days ago

Toast is looking for a Staff Data Scientist to build impactful data-driven models and insights for their restaurant platform.

Photo of the Rise User
LDMS Remote No location specified
Posted 10 days ago

As a Senior Product Owner at LDMS, you'll leverage your expertise in the financial sector to shape innovative digital lending solutions.

Photo of the Rise User

As a Senior Product Manager at Reuters, you'll lead the growth of specialized digital media content for industry professionals worldwide.

Photo of the Rise User

As the Strategic Bids & Contracts Manager at Meteor, you'll lead bid proposals and manage contract performance to align with organizational goals.

Photo of the Rise User

Join doinstruct as a Founders Associate to the CTO and play a vital role in optimizing technical operations and scaling products in a high-growth startup.

Photo of the Rise User
Apple Hybrid Cupertino, California, United States
Posted 13 days ago
Inclusive & Diverse
Diversity of Opinions
Work/Life Harmony
Dare to be Different
Reward & Recognition
Empathetic
Take Risks
Growth & Learning
Transparent & Candid
Mission Driven
Passion for Exploration
Feedback Forward
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Learning & Development
Paid Time-Off
Maternity Leave
Social Gatherings

Join Apple as a Product Manager to drive the vision for an innovative content planning platform that transforms global content operations.

Photo of the Rise User
Posted 10 days ago

GEICO is looking for an experienced Product Manager to drive innovative solutions in fraud and risk management within the insurance sector.

Posted 12 days ago

DWS Group is looking for a skilled Product Specialist/ Product Analyst to enhance their Asian credit business and contribute to product development.

Photo of the Rise User

Become a key player at Visa as a Solutions Manager focusing on innovative payment solutions for diverse clients.

Restaurant

266 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
April 23, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
S
7 people applied to Product Manager at Staff4Me
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry and Word Processing at MoxieIT
Photo of the Rise User
Someone from OH, Dayton just viewed Content Developer - Intern at Big Ideas Learning
Photo of the Rise User
Someone from OH, Pickerington just viewed Salesforce Lead at Bounteous
Photo of the Rise User
Someone from OH, Pickerington just viewed Industry Lead - High Tech (Salesforce) at Thunder
D
Someone from OH, Akron just viewed Junior Motion Designer at DEPT®
R
Someone from OH, Akron just viewed 2D Graphic and Motion Designer at Ruby Labs
Photo of the Rise User
Someone from OH, Columbus just viewed Customer Success Manager, US SLED at Dataminr
Photo of the Rise User
Someone from OH, Greenville just viewed Systems Engineer (Linux & Shell or Python scripting) at Visa
Photo of the Rise User
Someone from OH, Greenville just viewed Help Desk Technician - Youngstown at R.I.T.A.
Photo of the Rise User
Someone from OH, Mount Orab just viewed Backend Developer at G2i Inc.
Photo of the Rise User
Someone from OH, Cincinnati just viewed Product Marketing Manager at Cast & Crew
Photo of the Rise User
Someone from OH, Cincinnati just viewed Marketing Manager at Cast & Crew
o
Someone from OH, Cincinnati just viewed Administrative Assistant at osu
A
Someone from OH, Cincinnati just viewed Data Entry Clerk at Alphabe Insight Inc
Photo of the Rise User
Someone from OH, Cincinnati just viewed Machine Learning Engineer at Allstate
Photo of the Rise User
Someone from OH, Twinsburg just viewed Data Analyst/Power BI Developer at Datadog